˼¿Æ½¨¸´ÆäSD-WAN½â¾ö¹æ»®ÖеĶà¸ö·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3265£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.0£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3266£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3264£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÔËÐÐ×ÅCisco SD-WAN Solution Release 19.2.2֮ǰ°æ±¾µÄÒÔϲúÆ·£º


vBond Orchestrator Software

vEdge 100 Series Routers

vEdge 1000 Series Routers

vEdge 2000 Series Routers

vEdge 5000 Series Routers

vEdge Cloud Router Platform

vManage Network Management Software

vSmart Controller Software


·ì϶¸ÅÊö


Cisco SD-WAN SolutionÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ÍøÂçÀ©´ó½â¾ö¹æ»®¡£


½üÈÕ£¬Ë¼¿Æ°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÆäSD-WAN½â¾ö¹æ»®ÖеÄÎå¸ö·ì϶£¬ÆäÖÐÔ̺¬Èý¸ö¸ßΣ·ì϶£¬¸ÅÊöÈçÏ£º


CVE-2020-3265

Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖдæÔÚȨÏÞÐí¿ÉºÍ½Ó¼û½ÚÔìÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·Ö½øÐÐÊäÈëÑéÖ¤¡£±¾µØ¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÒªÇóÀûÓø÷ì϶»ñÈ¡rootȨÏÞ¡£


CVE-2020-3266

Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖеÄCLI´æÔÚºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»Óгä·Ö½øÐÐÊäÈëÑéÖ¤¡£±¾µØ¹¥»÷Õß¿Éͨ¹ý½øÐÐÉí·ÝÑéÖ¤²¢Ìá½»ÌØÔìµÄÊäÈëÀûÓø÷ì϶ÒÔrootȨÏÞÖ´ÐкÅÁî¡£


CVE-2020-3264

Cisco SD-WAN Solution software Release 19.2.2֮ǰ°æ±¾ÖдæÔÚ»º³åÇøÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚ²»³ä·ÖµÄÊäÈëÑéÖ¤¡£±¾µØ¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÁ÷Á¿ÀûÓø÷ì϶½Ó¼ûûÓÐÊÚȨµÄÐÅÏ¢»ò¶Ôϵͳ½øÐÐδÊÚȨµÄÅú¸Ä¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwpresc-ySJGvE9

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwclici-cvrQpH9v

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanbo-QKcABnS2


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/publicationListing.x